Code Injection in Flowise - #VU146559
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote user to access internal network resources and disclose sensitive information.
The vulnerability exists due to improper sandbox restrictions in the NodeVM custom JavaScript function environment when E2B sandbox is not configured and custom JavaScript functions can require overly permissive dependencies. A remote user can use allowed browser automation or database libraries to access internal network resources and disclose sensitive information.
The issue affects the fallback NodeVM execution path when E2B sandbox is not configured.